Multi-Party Charging Data Sharing Method, Device and Electronic Equipment Based on Attribute Encryption
Through the method of attribute encryption, dynamic generation of decryption components and decentralized key management is solved, and the problem of insufficient scalability and security in the traditional charging data sharing model is realized, flexible permission control and data security are realized, and suitable for large-scale multi-party charging data sharing.
Patent Information
- Application Number
- CN202411763166.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2044-12-03
AI Technical Summary
When facing large-scale users and complex permission needs, the traditional multi-party charging data sharing model lacks scalability and flexibility, and depends on the security risks of central management agencies, making it difficult to achieve dynamic permission management and data privacy protection.
Using an attribute-based encryption method, by generating data encapsulated ciphertext, secret value encapsulated ciphertext, first ciphertext and second ciphertext, dynamically generate decryption components using user attributes and access matrix to realize flexible permission control and decentralized key management.
It improves the adaptability and security of the system under complex permission requirements, avoids single point of failure, enhances data security and sharing flexibility, and is suitable for charging data sharing scenarios with large-scale multi-party participation.
Smart Images

Figure CN119628833B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power data access control, and particularly relates to a multi-party charging data sharing method, device, and electronic device based on attribute encryption. Background Art
[0002] With the popularization of new energy vehicles, the deployment of charging piles and the management of charging data have become crucial. New energy charging data plays an important role in supporting grid optimization, improving charging efficiency, and promoting the utilization of new energy. However, how to achieve efficient and flexible data sharing among multiple parties while ensuring data security has become the main challenge in the current technical field.
[0003] In the traditional multi-party charging data sharing model, the security and privacy of data often rely on a fixed access control list or a role-based access control model. These models usually adopt a static authorization mechanism, and manage users' access to data through predefined role and permission assignments. However, this method exposes many deficiencies in practical applications. First, it is difficult to expand the authorization scope. When the user scale or permission requirements change, the system needs to frequently update the authorization policy, resulting in complex management and low efficiency. The traditional authorization model is difficult to adapt to this large-scale demand, and the scalability of the system is limited, resulting in the inability to effectively support the access and management of a large number of users. Second, the access matching mechanism lacks dynamics and cannot adjust permissions according to changes in user attributes or real-time requirements, resulting in the system being rigid when dealing with complex permission requirements. In multi-party charging data sharing, the permission requirements of different users may change over time. For example, different users may need to access different data in different scenarios. However, the traditional static permission assignment cannot dynamically adjust according to the real-time requirements and attribute changes of users, resulting in an inflexible permission management process and difficulty in coping with complex access control requirements. In addition, the traditional authorization mechanism usually relies on a central management agency, and this single-point trust model has great security risks. Once the central agency is attacked or fails, the security of the entire system will face a serious threat, and the privacy of data is also difficult to guarantee. Summary of the Invention
[0004] In view of the above problems, the present invention proposes a multi-party charging data sharing method, device, and electronic device based on attribute encryption, which can flexibly meet the different permission requirements of a large number of users and avoid the rigidity problem caused by static permission assignment.
[0005] In order to achieve the above technical objectives and reach the above technical effects, the present invention is realized through the following technical solutions:
[0006] In the first aspect, the present invention provides a multi-party charging data sharing method based on attribute encryption, which is applied to the user side and includes:
[0007] Obtain ciphertext data, where the ciphertext data includes data encapsulation ciphertext, secret value encapsulation ciphertext, first ciphertext and second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters and a secret value. The secret value encapsulation ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key and an access matrix. The second ciphertext is generated based on public parameters, a master public key and a secret value;
[0008] If the public key of a user has been registered to the master public key, then based on the user's own private key, public parameters, secret value encapsulation ciphertext and second ciphertext, calculate a first decryption component;
[0009] If the user's own attributes meet the policy requirements corresponding to the access matrix, then based on the user's own private key and the first ciphertext, calculate a second decryption component;
[0010] Perform decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain charging data.
[0011] Combined with the first aspect, optionally, the expression of the public parameters is:
[0012]
[0013] where pp are public parameters; G represents a cyclic group; G T represents a bilinear group; the cyclic group G includes three subgroups G1, G2, G3; g1, g2, g3 are the generators of the three subgroups G1, G2, G3 respectively; the orders of the three subgroups G1, G2, G3 are p1, p2, p3, and the product of p1, p2, p3 is N, where N represents the order of the cyclic group; Z, h, A, B all represent group initialization parameters, Z = e(g1, g1) α , e represents a bilinear pairing operation, and α, t, τ, and β are four random numbers randomly selected in the integer domain Z N ; is the user attribute registration identifier, ω i is the i-th user attribute, ω i ∈U, i = 1, 2,... n, where n represents the total number of user attributes, and U is the set of all user attributes, is a random number randomly selected in the integer domain Z N ;
[0014] The expression of the master public key is:
[0015]
[0016] where, is the set of public key registration identifiers, and the elements in are the public keys T of registered users, where r is the private key of the registered user; is the set of user attribute registration identifiers. Each user attribute ω in the set U i is compared with the set of user attributes S submitted by the registered user. When the user attribute ω i ∈S, then 1 is written into the set ; when the user attribute ..., then is written into
[0017] Combined with the first aspect, optionally, the calculation formula for the data encapsulation ciphertext is:
[0018] C1 = data·Z s ;
[0019] Z = e(g1, g1) α ;
[0020] where C1 is the data encapsulation ciphertext; data is the charging data; s is the secret value;
[0021] The calculation formula for the secret value encapsulation ciphertext is:
[0022]
[0023] where C2 is the secret value encapsulation ciphertext.
[0024] Combined with the first aspect, optionally, the method for generating the first ciphertext includes the following steps:
[0025] Use the linear secret sharing scheme to convert the access policy into an access matrix M. Each row of the access matrix M is associated with the specified user attributes x1,..., x K ;
[0026] Based on the principle of h = h1h2, randomly select parameters h1 and h2 in the integer domain Z N ;
[0027] Randomly select parameters v2,..., v N in the integer domain Z n , and combine with the secret value s to construct a vector v,
[0028] Calculate the matrix sharing share u of the vector v, u = Mv, where the k-th row component u k of the matrix sharing share u is the matrix sharing share associated with the attribute x k ;
[0029] For each specified user attribute x1,..., x K , respectively calculate the corresponding first ciphertext C 3,k ,
[0030] Combined with the first aspect, optionally, the method for generating the second ciphertext includes the following steps:
[0031] Based on the secret value s, public parameters, and master public key, calculate the second ciphertext C4, and the calculation formula for the second ciphertext C4 is:
[0032]
[0033] Combined with the first aspect, optionally, the calculation formula for the first decryption component is:
[0034]
[0035] where D r is the first decryption component, C4 is the second ciphertext, C2 is the ciphertext encapsulating the secret value, r is the user's own private key, and s is the secret value.
[0036] Combined with the first aspect, optionally, the calculation formula for the second decryption component is:
[0037]
[0038] where D p is the second decryption component, is the intermediate parameter calculated based on the first ciphertext;
[0039] Intermediate parameter is obtained through the following method:
[0040] When the user's own attributes meet the policy requirements corresponding to the access matrix, calculate The first ciphertext C 3,k can be simplified to:
[0041] When the user's own attribute set S matches the matrix sharing share u 3,k in the first ciphertext C k , there must exist a weight vector ω S , such that M S is the subset of the access matrix extracted from the access matrix M corresponding to the attribute set S, and then obtain
[0042] Combined with the first aspect, optionally, the charging data is decrypted through the following formula:
[0043] Utilize D p and D r to calculate e(h, g1) st , and the adopted calculation formula is:
[0044] D p ·D r = e(h2, g1) st ·e(h1, g1) st = e(h, g1) st
[0045] Based on e(h, g1) st , data encapsulation ciphertext, secret value encapsulation ciphertext, and public parameters, calculate the charging data data according to the following formula:
[0046]
[0047] In a second aspect, the present invention provides a multi-party charging data sharing device based on attribute encryption, which is applied to the user side and includes:
[0048] A ciphertext data acquisition module, configured to acquire ciphertext data, where the ciphertext data includes data encapsulation ciphertext, secret value encapsulation ciphertext, first ciphertext, and second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters, and secret values. The secret value encapsulation ciphertext is generated based on public parameters and secret values. The first ciphertext is generated based on secret values, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and secret values;
[0049] A first decryption component calculation module, configured to calculate a first decryption component based on the user's own private key, public parameters, secret value encapsulation ciphertext, and second ciphertext if the user's public key has been registered to the master public key;
[0050] A second decryption component calculation module, configured to calculate a second decryption component based on the user's own private key and the first ciphertext if the user's own attributes meet the policy requirements corresponding to the access matrix;
[0051] A decryption module, configured to perform decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain the charging data.
[0052] In a third aspect, the present invention provides a multi-party charging data sharing system based on attribute encryption, including an authorization center, a cloud server, and a user side;
[0053] The authorization center generates ciphertext data and sends it to the cloud server;
[0054] The user side is configured to perform the following steps:
[0055] Obtain ciphertext data, where the ciphertext data includes data encapsulation ciphertext, secret value encapsulation ciphertext, first ciphertext, and second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters, and a secret value. The secret value encapsulation ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and a secret value;
[0056] If the public key of the user has been registered to the master public key, then based on the user's own private key, public parameters, secret value encapsulation ciphertext, and second ciphertext, calculate the first decryption component;
[0057] If the user's own attributes meet the policy requirements corresponding to the access matrix, then based on the user's own private key and the first ciphertext, calculate the second decryption component;
[0058] Perform decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain the charging data.
[0059] In a fourth aspect, the present invention provides an electronic device, including a storage medium and a processor;
[0060] The storage medium is used to store instructions;
[0061] The processor is used to operate according to the instructions to execute the method according to any one of the first aspects.
[0062] Compared with the prior art, the beneficial effects of the present invention are:
[0063] Traditional permission control schemes often rely on static access control lists or role-based access control. The present invention generates the first ciphertext based on a secret value, a master public key, and an access matrix, providing a dynamic and flexible permission control mechanism. The flexibility of the access matrix makes the allocation and update of permissions more convenient. It can adjust access permissions in real time according to changes in user attributes, realizing more refined and dynamic permission management. This innovation greatly improves the system's ability to handle complex permission requirements, especially suitable for multi-party charging data sharing scenarios with multiple participants and complex permission requirements.
[0064] The present invention innovatively introduces attribute matching into permission management and uses user attributes and policy vectors for fine-grained access control. Through this method, the encryption and decryption of charging data no longer depend on a single key, but are determined by the set of user attributes, greatly enhancing data security and sharing flexibility. It significantly improves the security of the system, enabling data to be decrypted only in the hands of users who meet specific conditions, thus effectively preventing illegal access and leakage of data.
[0065] Different from traditional methods, the present invention does not rely on a central key management agency, decentralizes the key management process, and dynamically generates and manages keys through users' registration information. After each user registers in the system, a unique key is generated based on their registered identity information. This mechanism avoids single-point failures and trust issues of the central agency, making the system more secure and resilient. Decentralized key management not only reduces the risk of key leakage but also simplifies the process of key distribution and management, and is particularly suitable for large-scale, multi-party charging data sharing application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings, where:
[0067] Figure 1 is a flowchart of a multi-party charging data sharing method according to an embodiment of the present invention;
[0068] Figure 2 is a data access flowchart of an application scenario according to an embodiment of the present invention;
[0069] Figure 3 is an execution timing diagram of a multi-party charging data sharing method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0070] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0071] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present invention, the descriptions of "first", "second", etc. are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first", "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the present invention.
[0072] Embodiment 1
[0073] In an embodiment of the present invention, a multi-party charging data sharing method based on attribute encryption is provided, which is applied to the user side and includes the following steps:
[0074] Step (1): Obtain ciphertext data, where the ciphertext data includes data encapsulation ciphertext, secret value encapsulation ciphertext, first ciphertext, and second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters, and a secret value. The secret value encapsulation ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and a secret value.
[0075] Step (2): If the public key of the user has been registered to the master public key, calculate a first decryption component based on the user's own private key, public parameters, secret value encapsulation ciphertext, and second ciphertext.
[0076] Step (3): If the user's own attributes meet the policy requirements corresponding to the access matrix, calculate a second decryption component based on the user's own private key and the first ciphertext.
[0077] Step (4): Perform decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain charging data.
[0078] In a specific implementation manner of the embodiment of the present invention, the expression of the public parameters is:
[0079]
[0080] where pp is the public parameter; G represents a cyclic group; G T represents a bilinear group; the cyclic group G includes three subgroups G1, G2, and G3; g1, g2, and g3 are the generators of the three subgroups G1, G2, and G3 respectively; the orders of the three subgroups G1, G2, and G3 are p1, p2, and p3, and the product of p1, p2, and p3 is N, where N represents the order of the cyclic group; Z, h, A, and B all represent group initialization parameters, Z = e(g1, g1) α , A = (g1g3) t , e represents a bilinear pairing operation, and α, t, τ, and β are four random numbers randomly selected in the integer domain Z N ; is the user attribute registration identifier, ω i is the i-th user attribute, ω i ∈U, i = 1, 2,... n, where n represents the total number of user attributes, and U is the set of all user attributes. is in the integer domain Z NA random number randomly selected from
[0081] The expression of the master public key is:
[0082]
[0083] Where is the public key registration identification set, The elements in are the public key T of the registered user, r is the private key of the registered user; is the user attribute registration identification set. Each user attribute ω in the set U i is compared with the user attribute set S submitted by the registered user. When the user attribute ω i ∈S, then write 1 into the set ; When the user attribute then write to write
[0084] In the specific implementation process, the public parameters and the master public key are both generated by the authorization center and sent to the cloud server. In a specific implementation manner of the embodiment of the present invention, the calculation formula of the data encapsulation ciphertext is:
[0085] C1 = data·Z s ;
[0086] Z = e(g1,g1) α ;
[0087] Where C1 is the data encapsulation ciphertext; data is the charging data; s is the secret value;
[0088] The calculation formula of the secret value encapsulation ciphertext is:
[0089]
[0090] Where C2 is the secret value encapsulation ciphertext.
[0091] In the specific implementation process, the data encapsulation ciphertext and the secret value encapsulation ciphertext are both generated by the data middleware.
[0092] In a specific implementation manner of the embodiment of the present invention, the method for generating the first ciphertext includes the following steps:
[0093] Use the linear secret sharing scheme to convert the access policy into an access matrix M. Each row of the access matrix M is associated with the specified user attributes x1,...,x K associated;
[0094] Based on the principle of h = h1h2, randomly in the integer domain Z NSelect parameters h1 and h2 from
[0095] Randomly select parameters v2,..., v in the integer domain Z N and, combined with the secret value s, construct the vector v n Calculate the matrix sharing share u of the vector v, u = Mv, where the k-th row component u
[0096] of the matrix sharing share u is the matrix sharing share associated with the attribute x k ; k
[0097] For each specified user attribute x1,..., x K , respectively calculate the corresponding first ciphertext C 3,k ,
[0098] In a specific implementation manner of the embodiment of the present invention, the method for generating the second ciphertext includes the following steps:
[0099] Based on the secret value s, public parameters, and the master public key, calculate the second ciphertext C4, and the calculation formula of the second ciphertext C4 is:
[0100]
[0101] In a specific implementation manner of the embodiment of the present invention, the calculation formula of the first decryption component is:
[0102]
[0103] where D r is the first decryption component, C4 is the second ciphertext, C2 is the ciphertext for encapsulating the secret value, r is the private key of the user itself, and s is the secret value.
[0104] In a specific implementation manner of the embodiment of the present invention, the calculation formula of the second decryption component is:
[0105]
[0106] where D p is the second decryption component, is the intermediate parameter calculated based on the first ciphertext;
[0107] The intermediate parameter is obtained by the following method:
[0108] When the attributes of the user itself meet the policy requirements corresponding to the access matrix, calculate The first ciphertext C 3,k can be simplified to:
[0109] When the attribute set S of the user himself matches the matrix sharing share u 3,k in k the first ciphertext C, there must exist a weight vector ω S such that M S is the access matrix subset corresponding to the attribute set S extracted from the access matrix M, and then
[0110] Combined with the first aspect, optionally, the charging data is decrypted and obtained through the following formula:
[0111] Using D p and D r calculate e(h, g1) st , and the calculation formula used is:
[0112] D p ·D r =e(h2, g1) st ·e(h1, g1) st =e(h, g1) st
[0113] Based on e(h, g1) st , the data encapsulation ciphertext, the secret value encapsulation ciphertext, and the public parameters, calculate the charging data data according to the following formula:
[0114]
[0115] Embodiment 2
[0116] Based on the same inventive concept as Embodiment 1, an attribute-based multi-party charging data sharing device is provided in an embodiment of the present invention, which is applied to the user side and includes:
[0117] A ciphertext data acquisition module, configured to acquire ciphertext data, where the ciphertext data includes a data encapsulation ciphertext, a secret value encapsulation ciphertext, a first ciphertext, and a second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters, and a secret value. The secret value encapsulation ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and a secret value;
[0118] A first decryption component calculation module, configured to calculate a first decryption component based on the user's own private key, public parameters, the secret value encapsulation ciphertext, and the second ciphertext if the user's public key has been registered to the master public key;
[0119] The second decryption component calculation module is used to calculate the second decryption component based on the user's own private key and the first ciphertext when the user's own attributes meet the policy requirements corresponding to the access matrix;
[0120] The decryption module is used to perform decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain charging data.
[0121] Embodiment 3
[0122] In an embodiment of the present invention, a multi-party charging data sharing system based on attribute encryption is provided, including an authorization center, a cloud server, and a user terminal;
[0123] The authorization center generates ciphertext data and sends it to the cloud server;
[0124] The user terminal is configured to perform the following steps:
[0125] Obtain ciphertext data, where the ciphertext data includes a data encapsulation ciphertext, a secret value encapsulation ciphertext, a first ciphertext, and a second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters, and a secret value. The secret value encapsulation ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and a secret value;
[0126] If the user's public key has been registered to the master public key, calculate the first decryption component based on the user's own private key, public parameters, secret value encapsulation ciphertext, and second ciphertext;
[0127] If the user's own attributes meet the policy requirements corresponding to the access matrix, calculate the second decryption component based on the user's own private key and the first ciphertext;
[0128] Perform decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain charging data.
[0129] The working principle of the multi-party charging data sharing system based on attribute encryption in the embodiment of the present invention will be described in detail below in conjunction with a specific embodiment.
[0130] Specifically, referring to Figure 1 and Figure 3 As shown, the multi-party charging data sharing system based on attribute encryption includes an authorization center, a data middle platform, a cloud server, and several user terminals:
[0131] The authorization center represents all user attributes involved in the charging data sharing access as a set U; initializes the pairing calculation parameters based on the composite order bilinear pairing operation, and the pairing calculation parameters include G, G T, N, g, e, where G represents a cyclic group, and G T represents a bilinear group, N represents the order of the cyclic group, g represents the generator of the cyclic group, and e represents the bilinear pairing operator.
[0132] Let G1, G2, and G3 respectively represent three subgroups of the cyclic group G, where g1, g2, and g3 are the generators of the three subgroups respectively; p1, p2, and p3 are the orders of the three subgroups respectively, and their product is N. Next, randomly select four random numbers in the integer domain Z N as the values of the parameters α, t, τ, and β, and calculate the group initialization parameters Z, h, A, and B, where Z = e(g1, g1) α , A = (g1g3) t , Initialize each user attribute ω i , where ω i ∈U, i = 1, 2, … n, and n represents the total number of user attributes, and calculate the attribute initialization parameter as a random number randomly selected in the integer domain Z N . Finally, obtain the public parameter pp:
[0133]
[0134] The authorization center receives the user's registration request: Specifically, the user randomly selects r in the integer domain Z N as its own private key, that is, sk = r; and submits as its own public key pk to the authorization center for registration. When the authorization center receives the user's registration request and the user's user attribute set S, it saves the user's public key T to the public key registration identification set of the authorization center Then, the authorization center compares each user attribute ω i in the set U with the user attribute set S submitted by the user. When the user attribute ω i ∈S, write 1 into the set ; when the user attribute , write into Finally, generate the master public key mpk of the authorization center. The expression of the master public key mpk is:
[0135]
[0136] The data middle platform encrypts the charging data using the master public key mpk. The charging data is represented as data, and calculates the data encapsulation ciphertext and the secret value encapsulation ciphertext respectively in combination with the secret value s to complete the data encapsulation:
[0137] C1 = data·Z s
[0138]
[0139] Among them, C1 is the data-encapsulated ciphertext, and C2 is the secret-value-encapsulated ciphertext.
[0140] The secret value s is a random number randomly selected by the data middle platform.
[0141] (3) Calculate the first ciphertext and the second ciphertext:
[0142] Use the linear secret sharing scheme to convert the access policy into an access matrix M. Each row of the access matrix M is associated with the specified user attributes x1,..., x K ; The access matrix M is used to perform the permission verification of the accessing user and dynamically control data access according to the user's user attributes.
[0143] Randomly select parameters h1 and h2 in the integer domain Z N . The parameters h1 and h2 must satisfy:
[0144] Randomly select n - 1 elements N in the integer domain Z for encapsulating the secret value s to construct a vector Calculate the matrix sharing share u of the vector v, u = Mv, where the k-th row component u k is the matrix sharing share associated with the attribute x k .
[0145] For each user attribute x1,..., x K respectively calculate the corresponding first ciphertext C 3,k , and the calculation formula of the first ciphertext C 3,k is:
[0146]
[0147] where k = 1, 2,... K;
[0148] Secondly, calculate the second ciphertext C4, and the calculation formula of the second ciphertext C4 is:
[0149]
[0150] Upload the first ciphertext C 3,k , the second ciphertext C4, the data-encapsulated ciphertext C1, and the secret-value-encapsulated ciphertext C2 to the cloud server for subsequent shared access by a large number of users.
[0151] (4) Calculate the first decryption component Dr :
[0152] Before requesting data access, the user must first verify the identity registration information. That is, the user performs operations based on their own private key r, the second ciphertext C4, and the secret value encapsulated ciphertext C2. If the public key corresponding to the user's own private key has been registered in the authorization center (i.e., the public key has been stored in the public key registration identification set ), then through the operation, the user can obtain the first decryption component D r , and the calculation formula of the first decryption component D r is:
[0153]
[0154] (5) Calculate the second decryption component D p :
[0155] When the user's own attributes meet the policy requirements corresponding to the access matrix, calculate The first ciphertext C 3,k can be simplified to: When the user's own attribute set S matches the matrix sharing share u 3,k in the first ciphertext C k , there must exist a weight vector ω S , such that M S is the access matrix subset corresponding to the attribute set S extracted from the access matrix M, and then obtain If the user's own attributes do not meet the policy requirements corresponding to the access matrix, then The first ciphertext C 3,k cannot be simplified, and thus the intermediate parameters cannot be calculated
[0156] Secondly, use the calculated to perform a bilinear pairing operation with A in the public parameters to obtain the second decryption component D p :
[0157]
[0158] In the above calculation of D p , the properties of the linear secret sharing matrix are implicitly utilized.
[0159] (6) Charging data decryption and sharing:
[0160] The user uses the decryption components D r and D p to construct a decryption equation to obtain the clear text of the charging data.
[0161] Since h = h1h2, the user can utilize D p and D r to calculate e(h, g1) st :
[0162] D p ·D r = e(h2, g1) st ·e(h1, g1) st = e(h, g1) st
[0163] Furthermore, the user continues to construct the following decryption equation to obtain the plaintext charging data data:
[0164]
[0165] The decryption process is based on the user's attributes and permission policies. Only when the user's attributes meet the policy requirements corresponding to the access matrix can the charging data be decrypted.
[0166] Based on the above calculation and processing process, the following is the evaluation and analysis of the present invention.
[0167] The construction of the present invention's solution is based on the Subgroup Decision Assumption (SDA), that is, given an element u ∈ G and a bilinear pair e(u, g), determine whether u belongs to a subgroup G1, G2 or G3 of G. The difficulty of this assumption means that even if an attacker can access the public key and related bilinear pair values, it is impossible to effectively distinguish which subgroup an element belongs to. Consider an adversary A whose goal is to break the encrypted data in the system or bypass the access control of the permission matrix. The security objectives of the present solution are defined as indistinguishability and unforgeability respectively. Indistinguishability: The attacker cannot distinguish between two encrypted data C0 and C1, even if it knows the corresponding attributes and partial system parameters of these data: Unforgeability: The attacker cannot forge a decryption key that can decrypt the ciphertext without valid attributes.
[0168] Suppose attacker A can distinguish between two ciphertexts C0 and C1, then an algorithm B can be constructed to solve the SDA problem, thus breaking the subgroup decision assumption. Due to the difficulty of the SDA assumption, this situation cannot occur, so the attacker cannot successfully distinguish the ciphertext. Suppose attacker A can generate a valid decryption key sk to decrypt ciphertexts C0 and C1 without legitimate attributes, and we can construct another algorithm B' to crack the SDA problem. Due to the difficulty of the SDA assumption, the attacker cannot generate a valid decryption key, ensuring the unforgeability of the system. Based on the difficult subgroup decision problem, the multi-party charging data sharing scheme described in the present invention is secure in terms of indistinguishability and unforgeability. Without the ability to crack the SDA problem, the attacker cannot effectively distinguish the ciphertext or generate a forged decryption key, thus ensuring the security of the data sharing process.
[0169] Embodiment 4
[0170] Based on the same inventive concept as in Embodiment 1, an electronic device is provided in an embodiment of the present invention, including a storage medium and a processor;
[0171] The storage medium is used to store instructions;
[0172] The processor is used to operate according to the instructions to execute the method according to any one of Embodiment 1.
[0173] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0174] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0175] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means which implements the functions specified in one or more of the processes Figure 1 steps or a plurality of steps and / or boxes Figure 1 boxes or a plurality of boxes.
[0176] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the processes Figure 1 steps or a plurality of steps and / or boxes Figure 1 boxes or a plurality of boxes.
[0177] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Those of ordinary skill in the art, under the inspiration of the present invention and without departing from the spirit and scope of the present invention as defined by the claims, can still make many forms, all of which fall within the protection scope of the present invention.
[0178] The basic principles, main features and advantages of the present invention have been shown and described above. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the description in the specification are only used to illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and all of these changes and improvements fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A multi-party charging data sharing method based on attribute encryption, characterized in that Applied to the user side, including: Obtain ciphertext data, where the ciphertext data includes data encapsulation ciphertext, secret value encapsulation ciphertext, first ciphertext, and second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters, and a secret value. The secret value encapsulation ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and a secret value; If the user's public key has been registered to the master public key, calculate a first decryption component based on the user's own private key, public parameters, secret value encapsulation ciphertext, and second ciphertext; If the user's own attributes meet the policy requirements corresponding to the access matrix, calculate a second decryption component based on the user's own private key and the first ciphertext; Perform decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain charging data; The expression of the public parameters is: where pp is a public parameter; G represents a cyclic group; G T represents a bilinear group; the cyclic group G includes three subgroups G1, G2, and G3; g1, g2, and g3 are the generators of the three subgroups G1, G2, and G3 respectively; the orders of the three subgroups G1, G2, and G3 are p1, p2, and p3, and the product of p1, p2, and p3 is N, where N represents the order of the cyclic group; Z, h, A, and B are all group initialization parameters, and Z = e(g1, g1) α , A = (g1g3) t , e represents the bilinear pairing operation, and α, t, τ, and β are four random numbers randomly selected from the integer domain Z N ; is the user attribute registration identifier, ω i is the i-th user attribute, ω i ∈U, i = 1, 2,..., n, where n represents the total number of user attributes, and U is the set of all user attributes is a random number randomly selected from the integer domain Z N ; The expression of the master public key is: Among them, is the public key registration identification set, the elements in which are the public keys T of registered users, r is the private key of the registered user; is the user attribute registration identification set. Each user attribute ω in the set U i is compared with the user attribute set S submitted by the registered user. When the user attribute ω i ∈S, then 1 is written into the set ; when the user attribute then, is written into 2. The multi-party charging data sharing method based on attribute encryption according to claim 1, characterized in that: The calculation formula of the data encapsulation ciphertext is: C1 = data·Z s ; Z = e(g1, g1) α ; Wherein, C1 is the data encapsulation ciphertext; data is the charging data; s is the secret value; The calculation formula of the secret value encapsulation ciphertext is: Wherein, C2 is the secret value encapsulation ciphertext.
3. The method for sharing multi-party charging data based on attribute encryption according to claim 2, wherein, The method for generating the first ciphertext includes the following steps: Convert the access policy into an access matrix M using a linear secret sharing scheme, where each row of the access matrix M is associated with a specified user attribute x1,...,x K is associated with; Taking h = h1h2 as the principle, randomly select parameters h1 and h2 in the integer domain Z N ; Randomly select parameters v2,..., v in the integer domain Z N and, combined with the secret value s, construct the vector v n Calculate the matrix sharing share u of vector v, u = Mv, where the k-th row component u of the matrix sharing share u k is the matrix sharing share associated with attribute x k ; For each specified user attribute x1,..., x K , respectively calculate the corresponding first ciphertext C 3,k , 4. The multi-party charging data sharing method based on attribute encryption according to claim 3, wherein The method for generating the second ciphertext includes the following steps: Based on the secret value s, public parameters, and the master public key, calculate the second ciphertext C4. The calculation formula of the second ciphertext C4 is:
5. The method for sharing multi-party charging data based on attribute encryption according to claim 4, characterized in that: The calculation formula of the first decryption component is: Among them, D r is the first decryption component, C4 is the second ciphertext, C2 is the secret value encapsulated ciphertext, r is the user's own private key, and s is the secret value.
6. The multi-party charging data sharing method based on attribute encryption according to claim 3, characterized in that: The calculation formula of the second decryption component is: Among them, D p is the second decryption component, is an intermediate parameter calculated based on the first ciphertext; Intermediate parameter is calculated by the following method: When the attributes of the user himself meet the policy requirements corresponding to the access matrix, calculate the first ciphertext C 3,k can be simplified to: When the attribute set S of the user himself matches the matrix sharing share u 3,k in k it is inevitable that there exists a weight vector ω S such that M S is the access matrix subset corresponding to the attribute set S extracted from the access matrix M, and then 7. A multi-party charging data sharing method based on attribute encryption according to claim 6, characterized in that: The charging data is obtained by decrypting through the following formula: Using D p and D r calculate e(h, g1) st , and the calculation formula adopted is: D p ·D r = e(h2, g1) st ·e(h1, g1) st = e(h, g1) st Based on e(h, g1) st , the encrypted data ciphertext, the encrypted secret value, and the public parameters are used to calculate the charging data data according to the following formula:
8. A multi-party charging data sharing device based on attribute encryption, characterized in that Applied to the user side, including: A ciphertext data acquisition module for acquiring ciphertext data, where the ciphertext data includes data encapsulation ciphertext, secret value encapsulation ciphertext, first ciphertext, and second ciphertext. The data encapsulation ciphertext is generated based on charging data, public parameters, and a secret value. The secret value encapsulation ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and a secret value; A first decryption component calculation module for calculating a first decryption component based on the user's own private key, public parameters, secret value encapsulation ciphertext, and second ciphertext if the user's public key has been registered to the master public key; A second decryption component calculation module for calculating a second decryption component based on the user's own private key and the first ciphertext if the user's own attributes meet the policy requirements corresponding to the access matrix; A decryption module for performing decryption calculation on the data encapsulation ciphertext based on the first decryption component and the second decryption component to obtain charging data; The expression of the public parameters is: where pp is a public parameter; G represents a cyclic group; G T represents a bilinear group; the cyclic group G includes three subgroups G1, G2, and G3; g1, g2, and g3 are the generators of the three subgroups G1, G2, and G3 respectively; the orders of the three subgroups G1, G2, and G3 are p1, p2, and p3, and the product of p1, p2, and p3 is N, where N represents the order of the cyclic group; Z, h, A, and B are all group initialization parameters, and Z = e(g1, g1) α , A = (g1g3) t , e represents the bilinear pairing operation, and α, t, τ, and β are four random numbers randomly selected from the integer domain Z N ; is the user attribute registration identifier, ω i is the i-th user attribute, ω i ∈U, where i = 1, 2,..., n, n represents the total number of user attributes, and U is the set of all user attributes is a random number randomly selected from the integer domain Z N ; The expression of the master public key is: Among them, is the public key registration identification set, the elements in which are the public keys T of registered users, and r is the private key of the registered user; is the user attribute registration identification set. Each user attribute ω in the set U i is compared with the user attribute set S submitted by the registered user. When the user attribute ω i ∈S, then 1 is written into the set ; when the user attribute ..., then is written into ...
9. A multi-party charging data sharing system based on attribute encryption, characterized in that, Including an authorization center, a cloud server, and a user side; The authorization center generates ciphertext data and sends it to the cloud server; The user side is configured to perform the following steps: Obtain ciphertext data, where the ciphertext data includes data-encapsulated ciphertext, secret-value-encapsulated ciphertext, first ciphertext, and second ciphertext. The data-encapsulated ciphertext is generated based on charging data, public parameters, and a secret value. The secret-value-encapsulated ciphertext is generated based on public parameters and a secret value. The first ciphertext is generated based on a secret value, a master public key, and an access matrix. The second ciphertext is generated based on public parameters, a master public key, and a secret value; If the public key of the user has been registered to the master public key, calculate a first decryption component based on the user's own private key, public parameters, secret-value-encapsulated ciphertext, and second ciphertext; If the user's own attributes meet the policy requirements corresponding to the access matrix, calculate a second decryption component based on the user's own private key and the first ciphertext; Perform decryption calculation on the data-encapsulated ciphertext based on the first decryption component and the second decryption component to obtain charging data; The expression of the public parameters is: Among them, pp is a public parameter; G represents a cyclic group; G T represents a bilinear group; the cyclic group G includes three subgroups G1, G2, G3; g1, g2, g3 are the generators of the three subgroups G1, G2, G3 respectively; the orders of the three subgroups G1, G2, G3 are p1, p2, p3, and the product of p1, p2, p3 is N, where N represents the order of the cyclic group; Z, h, A, B all represent group initialization parameters, and Z = e(g1, g1) α , A = (g1g3) t , e represents the bilinear pairing operation, and α, t, τ, and β are four random numbers randomly selected in the integer domain Z N ; U ωi is the user attribute registration identifier, ω i is the i-th user attribute, ω i ∈U, i = 1, 2, … n, where n represents the total number of user attributes, and U is the set of all user attributes is a random number randomly selected in the integer domain Z N ; The expression of the master public key is: Among them, is the public key registration identification set, and the elements in it are the public keys T of registered users, and r is the private key of the registered user; is the user attribute registration identification set. Each user attribute ω in the set U i is compared with the user attribute set S submitted by the registered user. When the user attribute ω i ∈ S, then 1 is written into the set ; when the user attribute is not in S, then is written with 10. An electronic device, characterized in that, Include a storage medium and a processor; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the method according to any one of claims 1-7.
Citation Information
Patent Citations
Data sharing method, device and system, client and storage medium
CN111163036A
Intelligent power grid electricity utilization information encryption method and system based on attribute base
CN115529123A